Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
References
Link | Resource |
---|---|
https://github.com/containous/traefik/pull/3790 | Third Party Advisory |
https://github.com/containous/traefik/pull/3790/commits/113250ce5735d554c502ca16fb03bb9119ca79f1 | Third Party Advisory |
https://github.com/containous/traefik/pull/3790/commits/368bd170913078732bde58160f92f202f370278b | Third Party Advisory |
https://github.com/containous/traefik/releases/tag/v1.6.6 | Release Notes |
https://github.com/containous/traefik/pull/3790 | Third Party Advisory |
https://github.com/containous/traefik/pull/3790/commits/113250ce5735d554c502ca16fb03bb9119ca79f1 | Third Party Advisory |
https://github.com/containous/traefik/pull/3790/commits/368bd170913078732bde58160f92f202f370278b | Third Party Advisory |
https://github.com/containous/traefik/releases/tag/v1.6.6 | Release Notes |
Configurations
History
21 Nov 2024, 03:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/containous/traefik/pull/3790 - Third Party Advisory | |
References | () https://github.com/containous/traefik/pull/3790/commits/113250ce5735d554c502ca16fb03bb9119ca79f1 - Third Party Advisory | |
References | () https://github.com/containous/traefik/pull/3790/commits/368bd170913078732bde58160f92f202f370278b - Third Party Advisory | |
References | () https://github.com/containous/traefik/releases/tag/v1.6.6 - Release Notes |
Information
Published : 2018-08-21 01:29
Updated : 2024-11-21 03:51
NVD link : CVE-2018-15598
Mitre link : CVE-2018-15598
CVE.ORG link : CVE-2018-15598
JSON object : View
Products Affected
traefik
- traefik
CWE
CWE-287
Improper Authentication